Beacon Mutual Insurance
bd_da7048f19e46b32f · schema v1 · pii pii-v1
Full breach record for Beacon Mutual Insurance →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
MAJOR DATA LEAK – Beacon Mutual Insurance Company EXPOSED: 275 GB (296,228,795,086 bytes) of highly sensitive internal data Beacon Mutual Insurance Company (Warwick, RI) – the primary workers' compensation insurer for Rhode Island businesses (also operating in MA & CT) – has suffered a massive data compromise. The leaked archive contains approximately 275 GB of uncompressed/internal files and includes the following categories of highly confidential information: Internal corporate documents and correspondence Complete financial statements and reports (2018–2025) Full employee list with personal details Confidential agreements, NDAs, vendor contracts, and partnership documents Detailed claims data: workers' compensation payouts, injury reports, medical records tied to claims Client / policyholder database: business information, insurance policies, payment history Personally identifiable information (PII) of individuals (employees, claimants, insured workers) – names, SSNs, addresses, dates of birth, contact details, etc. Training materials, internal manuals, compliance & safety documentation Multiple system backups and database dumps ...and much more internal operational content
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jan 31, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteinc_ransombd_5b90158bd9f951672026-01-14 · +17dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Massachusetts State AGbd_5d7dc416180d53c82026-05-18 · +107dVerified by operator
- Montana State AGbd_88cdbba0a563b7f12026-05-18 · +107dVerified
- Vermont State AGbd_8abe1f6930c743e62026-05-18 · +107dVerified by operator
- California State AGbd_9212ea1e5259bdac2026-05-18 · +107dVerified by operator
Show 5 more filings ↓Show fewer ↑up to 108d gap
- Indiana State AGbd_96f08282e4c86e4a2026-05-18 · +107dVerified by operator
- Nebraska State AGbd_acbc06cd15404c7b2026-05-18 · +107dVerified
- Maine State AGbd_e4cb15dcb1bd517c2026-05-18 · +107dVerified by operator
- New Hampshire State AGbd_ffd3dfb51f7f7e862026-05-18 · +107dVerified by operator
- Texas State AGbd_a561b8d222dfacc42026-05-19 · +108dVerified
Filing propagation · 10 filings · 9 states
View merged incident ↗Pattern: first filing Jan 31, last May 19 (TX) — a 108-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.